Local Policy for Desktop Support Group

S

Sean

I've been researching this scenario and so far have not been able to come up
with a way to do it.

I need to have a local account called DesktopSupport or something along
those lines that can install/update device drivers, use run-as to
uninstall/reinstall software that requires administrator rights (initially
deployed under admin context with SMS), etc.. however, I need to restrict
the account from being able to add members to local administrators group.

Is their a way to restrict a member of the local administrators group from
managing the local administrators group?
 
C

Colin Nash [MVP]

Sean said:
I've been researching this scenario and so far have not been able to come
up with a way to do it.

I need to have a local account called DesktopSupport or something along
those lines that can install/update device drivers, use run-as to
uninstall/reinstall software that requires administrator rights (initially
deployed under admin context with SMS), etc.. however, I need to restrict
the account from being able to add members to local administrators group.

Is their a way to restrict a member of the local administrators group from
managing the local administrators group?

Either make them "Power Users" - which probably won't work for all software
installations, or consider using Group Policy (if you have a domain) to
define the memberships of the Administrators group. See
http://support.microsoft.com/?kbid=279301
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top